Manage Clients
A Client in Keycloak represents an application or service that can request authentication. Each client is registered within a Realm and configured with a specific protocol (OpenID Connect or SAML).
TOC
Client TypesCreate an OIDC ClientCreate a SAML ClientClient Secret ManagementView or Regenerate a Client SecretClient Secret RotationProtocol MappersAdd a Protocol MapperClient ScopesDefault vs Optional ScopesCreate a Client ScopeAssign a Client Scope to a ClientEvaluate ScopesService AccountsEnable a Service AccountObtain a Token with Service AccountClient PoliciesBuilt-in ProfilesCreate a Client PolicyClient Types
Create an OIDC Client
- Log in to the Keycloak Admin Console and select the target Realm.
- Click Clients in the left navigation bar.
- Click Create client.
- Set Client type to
OpenID Connect. - Enter a Client ID (for example,
my-web-app). - Click Next.
- Configure client authentication:
- Enable Client authentication for confidential clients.
- Disable it for public clients.
- Select the appropriate Authentication flow checkboxes:
- Standard flow (Authorization Code) — recommended for most applications.
- Direct access grants — for trusted applications that handle user credentials directly.
- Service accounts roles — for machine-to-machine authentication.
- Click Next.
- Set Valid redirect URIs (for example,
https://my-app.example.com/*). - Set Web origins for CORS (for example,
https://my-app.example.com). - Click Save.
Create a SAML Client
- In the Admin Console, click Clients > Create client.
- Set Client type to
SAML. - Enter the Client ID — this must match the Service Provider (SP) Entity ID (for example,
https://my-app.example.com/saml/metadata). - Click Save.
- Configure the following in the client Settings tab:
- In the Keys tab, configure encryption keys if your SP requires encrypted assertions.
Client Secret Management
For confidential clients, Keycloak generates a client secret automatically.
View or Regenerate a Client Secret
- In the Admin Console, go to Clients and select the target client.
- Click the Credentials tab.
- The current client secret is displayed. Click Regenerate to create a new secret.
Clicking Regenerate without a rotation policy in place immediately invalidates the previous secret. All applications using the old secret must be updated before they can authenticate.
Client Secret Rotation
Client secret rotation is a separate, policy-controlled mechanism that allows zero-downtime secret updates. When rotation is configured, Keycloak maintains multiple active secrets simultaneously during a transition period.
Client secret rotation is not the same as clicking Regenerate. Rotation is governed by a client policy that controls the rotation period and the number of active secrets. Without a rotation policy, regenerating a secret is an immediate, disruptive replacement. Configure a rotation policy via Client Policies before relying on zero-downtime secret updates.
To use client secret rotation:
- Create a client policy with a Secret Rotation executor (see Client Policies below).
- Configure the rotation parameters:
- Secret expiration period — How long a secret remains valid after creation.
- Rotated secret expiration period — How long the previous (rotated-out) secret remains valid alongside the new one.
- Remaining expiration period — Minimum remaining validity to trigger rotation.
- Apply the policy to the target clients.
- When the policy triggers rotation, Keycloak generates a new secret while keeping the previous secret valid for the configured grace period.
- Update your application to use the new secret within the grace period.
Protocol Mappers
Protocol Mappers control what claims are included in the tokens (OIDC) or assertions (SAML) issued for a client.
Add a Protocol Mapper
- In the client's detail view, click the Client scopes tab.
- Click the dedicated scope (for example,
my-web-app-dedicated). - Click Configure a new mapper or Add mapper > By configuration.
- Select the mapper type:
- Configure the mapper name, token claim name, and claim type.
- Click Save.
Client Scopes
Client Scopes define reusable sets of protocol mappers and role scope mappings that can be shared across multiple clients.
Default vs Optional Scopes
Create a Client Scope
- In the Admin Console, go to Client scopes.
- Click Create client scope.
- Enter a Name (for example,
custom-profile). - Set Protocol to
OpenID ConnectorSAML. - Set Include in token scope to
Onif the scope name should appear in the token'sscopeclaim. - Click Save.
- Add protocol mappers to define what claims this scope provides.
Assign a Client Scope to a Client
- In the client's detail view, click the Client scopes tab.
- Click Add client scope.
- Select the scope and set it as Default or Optional.
- Click Add.
Evaluate Scopes
The Evaluate sub-tab in the client scopes view lets you preview the exact token content for a given user and scope combination, which is useful for debugging token claim issues.
Service Accounts
A Service Account allows a confidential client to authenticate and obtain tokens without a user context (using the client_credentials grant).
Enable a Service Account
- In the client Settings tab, enable Service accounts roles.
- Click Save.
- Go to the Service account roles tab.
- Assign realm or client roles to define what the service account can access.
Obtain a Token with Service Account
Client Policies
Client Policies allow administrators to enforce rules on client configurations. A policy consists of conditions (when the policy applies) and profiles (what rules to enforce).
Built-in Profiles
Keycloak includes profiles for common compliance standards:
Create a Client Policy
- Go to Realm Settings > Client policies tab.
- Click Create policy.
- Enter a name and description.
- Add conditions to define which clients the policy applies to (for example, by client role, client scope, or client access type).
- Add profiles to define the rules enforced on matching clients.
- Click Save.